• Just looked at error logs on one site. I saw a warning of an attack. But it’s MY own IP. I logged into the admin so I know it’s not a spoof. I’m concerned how my IP appears as an attacker.

    15:47:18 2013] [error] [client 173.******] ModSecurity: Warning. Pattern match "(?:\\b(?:(?:type\\b\\W*?\\b(?:text\\b\\W*?\\b(?:j(?:ava)?|ecma|vb)|application\\b\\W*?\\bx-(?:java|vb))script|c(?:opyparentfolder|reatetextrange)|get(?:special|parent)folder|iframe\\b.{0,100}?\\bsrc)\\b|on(?:(?:mo(?:use(?:o(?:ver|ut)|down|move|up)|ve)|key(?:press|d ..." at ARGS:content. [file "/etc/httpd/modsecurity.d/modsecurity_crs_40_generic_attacks.conf"] [line "102"] [id "950004"] [msg "Cross-site Scripting (XSS) Attack"] [data "onmouseover="] [severity "CRITICAL"] [tag "WEB_ATTACK/XSS"] [hostname "www.xxxxxxxxx.com"] [uri "/wp-admin/post.php"] [unique_id "G5NttMy8ZAQAAEmMx0kAAAAk"]

    (I was hesitating on posting it in full but thought you may need to analyze it all to know what is going on.

Viewing 2 replies - 1 through 2 (of 2 total)
Viewing 2 replies - 1 through 2 (of 2 total)
  • The topic ‘XSS attack … from ME?’ is closed to new replies.