최근 HTTP ERROR 500 가 발생되네요
페이지 정보
본문
일단 서버에 AAI 설치해서 사용을 하는데,
어느날부터인가 500에러가 발생하네요
뭔하고 하고 에러내용을 파악해보는데 요런것들이 error_log에 적혀있는데 누군가 해킹을 한다거나
파일을 올린다거나 해서 이런 오류가 발생하는 걸까요???
[Tue Sep 24 11:27:50.357015 2019] [:error] [pid 2956:tid 140456679655168] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "47"] [id "960015"] [rev "1"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_ACCEPT"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-JmVb7RqOO9gTmuAABQAAAA4"]
[Tue Sep 24 11:27:50.369218 2019] [:error] [pid 2956:tid 140456679655168] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator LT matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "33"] [id "981203"] [msg "Inbound Anomaly Score (Total Inbound Score: 2, SQLi=0, XSS=0): Request Missing an Accept Header"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-JmVb7RqOO9gTmuAABQAAAA4"]
[Tue Sep 24 11:27:50.524709 2019] [:error] [pid 2956:tid 140456671262464] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "47"] [id "960015"] [rev "1"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_ACCEPT"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-JmVb7RqOO9gTmuAABgAAAA8"]
[Tue Sep 24 11:27:50.536400 2019] [:error] [pid 2956:tid 140456671262464] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator LT matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "33"] [id "981203"] [msg "Inbound Anomaly Score (Total Inbound Score: 2, SQLi=0, XSS=0): Request Missing an Accept Header"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-JmVb7RqOO9gTmuAABgAAAA8"]
[Tue Sep 24 11:27:50.709257 2019] [:error] [pid 2956:tid 140456662869760] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "47"] [id "960015"] [rev "1"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_ACCEPT"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-JmVb7RqOO9gTmuAABwAAABA"]
[Tue Sep 24 11:27:50.721362 2019] [:error] [pid 2956:tid 140456662869760] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator LT matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "33"] [id "981203"] [msg "Inbound Anomaly Score (Total Inbound Score: 2, SQLi=0, XSS=0): Request Missing an Accept Header"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-JmVb7RqOO9gTmuAABwAAABA"]
[Tue Sep 24 11:27:50.842070 2019] [:error] [pid 2956:tid 140456654477056] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "47"] [id "960015"] [rev "1"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_ACCEPT"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-JmVb7RqOO9gTmuAACAAAABE"]
[Tue Sep 24 11:27:50.853840 2019] [:error] [pid 2956:tid 140456654477056] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator LT matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "33"] [id "981203"] [msg "Inbound Anomaly Score (Total Inbound Score: 2, SQLi=0, XSS=0): Request Missing an Accept Header"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-JmVb7RqOO9gTmuAACAAAABE"]
[Tue Sep 24 11:27:51.373121 2019] [:error] [pid 2956:tid 140456646084352] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "47"] [id "960015"] [rev "1"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_ACCEPT"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-J2Vb7RqOO9gTmuAACQAAABI"]
[Tue Sep 24 11:27:51.386184 2019] [:error] [pid 2956:tid 140456646084352] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator LT matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "33"] [id "981203"] [msg "Inbound Anomaly Score (Total Inbound Score: 2, SQLi=0, XSS=0): Request Missing an Accept Header"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-J2Vb7RqOO9gTmuAACQAAABI"]
[Tue Sep 24 11:27:51.499698 2019] [:error] [pid 2956:tid 140456637691648] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "47"] [id "960015"] [rev "1"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_ACCEPT"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-J2Vb7RqOO9gTmuAACgAAABM"]
[Tue Sep 24 11:27:51.511788 2019] [:error] [pid 2956:tid 140456637691648] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator LT matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "33"] [id "981203"] [msg "Inbound Anomaly Score (Total Inbound Score: 2, SQLi=0, XSS=0): Request Missing an Accept Header"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-J2Vb7RqOO9gTmuAACgAAABM"]
[Tue Sep 24 11:27:51.681839 2019] [:error] [pid 2956:tid 140456629298944] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "47"] [id "960015"] [rev "1"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_ACCEPT"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-J2Vb7RqOO9gTmuAACwAAABQ"]
[Tue Sep 24 11:27:51.693614 2019] [:error] [pid 2956:tid 140456629298944] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator LT matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "33"] [id "981203"] [msg "Inbound Anomaly Score (Total Inbound Score: 2, SQLi=0, XSS=0): Request Missing an Accept Header"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-J2Vb7RqOO9gTmuAACwAAABQ"]
[Tue Sep 24 11:27:52.996530 2019] [:error] [pid 2956:tid 140456620906240] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "47"] [id "960015"] [rev "1"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_ACCEPT"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/calculate_lte.php"] [unique_id "XYl-KGVb7RqOO9gTmuAADAAAABU"]
[Tue Sep 24 11:27:53.008689 2019] [:error] [pid 2956:tid 140456620906240] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator LT matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "33"] [id "981203"] [msg "Inbound Anomaly Score (Total Inbound Score: 2, SQLi=0, XSS=0): Request Missing an Accept Header"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/calculate_lte.php"] [unique_id "XYl-KGVb7RqOO9gTmuAADAAAABU"]
[Tue Sep 24 11:27:55.102873 2019] [:error] [pid 2956:tid 140456612513536] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "47"] [id "960015"] [rev "1"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_ACCEPT"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-K2Vb7RqOO9gTmuAADQAAABY"]
[Tue Sep 24 11:27:55.115847 2019] [:error] [pid 2956:tid 140456612513536] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator LT matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "33"] [id "981203"] [msg "Inbound Anomaly Score (Total Inbound Score: 2, SQLi=0, XSS=0): Request Missing an Accept Header"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-K2Vb7RqOO9gTmuAADQAAABY"]
[Tue Sep 24 11:27:55.815534 2019] [:error] [pid 2956:tid 140456604120832] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "47"] [id "960015"] [rev "1"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_ACCEPT"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-K2Vb7RqOO9gTmuAADgAAABc"]
[Tue Sep 24 11:27:55.827670 2019] [:error] [pid 2956:tid 140456604120832] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator LT matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "33"] [id "981203"] [msg "Inbound Anomaly Score (Total Inbound Score: 2, SQLi=0, XSS=0): Request Missing an Accept Header"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-K2Vb7RqOO9gTmuAADgAAABc"]
[Tue Sep 24 11:27:55.985536 2019] [:error] [pid 2956:tid 140456595728128] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "47"] [id "960015"] [rev "1"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_ACCEPT"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-K2Vb7RqOO9gTmuAADwAAABg"]
[Tue Sep 24 11:27:55.997490 2019] [:error] [pid 2956:tid 140456595728128] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator LT matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "33"] [id "981203"] [msg "Inbound Anomaly Score (Total Inbound Score: 2, SQLi=0, XSS=0): Request Missing an Accept Header"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-K2Vb7RqOO9gTmuAADwAAABg"]
[Tue Sep 24 11:27:56.189866 2019] [:error] [pid 2956:tid 140456872425216] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "47"] [id "960015"] [rev "1"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_ACCEPT"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-LGVb7RqOO9gTmuAAEAAAAAA"]
[Tue Sep 24 11:27:56.201379 2019] [:error] [pid 2956:tid 140456872425216] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator LT matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "33"] [id "981203"] [msg "Inbound Anomaly Score (Total Inbound Score: 2, SQLi=0, XSS=0): Request Missing an Accept Header"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-LGVb7RqOO9gTmuAAEAAAAAA"]
[Tue Sep 24 11:27:56.389316 2019] [:error] [pid 2956:tid 140456864032512] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "47"] [id "960015"] [rev "1"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_ACCEPT"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-LGVb7RqOO9gTmuAAEQAAAAE"]
[Tue Sep 24 11:27:56.400991 2019] [:error] [pid 2956:tid 140456864032512] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator LT matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "33"] [id "981203"] [msg "Inbound Anomaly Score (Total Inbound Score: 2, SQLi=0, XSS=0): Request Missing an Accept Header"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-LGVb7RqOO9gTmuAAEQAAAAE"]
[Tue Sep 24 11:27:56.559447 2019] [:error] [pid 2956:tid 140456855639808] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "47"] [id "960015"] [rev "1"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_ACCEPT"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-LGVb7RqOO9gTmuAAEgAAAAI"]
[Tue Sep 24 11:27:56.571273 2019] [:error] [pid 2956:tid 140456855639808] [client 115.23.88.188:33226] [client 115.23.88.188] ModSecurity: Warning. Operator LT matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "33"] [id "981203"] [msg "Inbound Anomaly Score (Total Inbound Score: 2, SQLi=0, XSS=0): Request Missing an Accept Header"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "XYl-LGVb7RqOO9gTmuAAEgAAAAI"]
[Tue Sep 24 11:29:44.853926 2019] [:error] [pid 3620:tid 140457073518336] [client 115.23.88.188:33227] [client 115.23.88.188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "47"] [id "960015"] [rev "1"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_ACCEPT"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "@C1WJLAAAAME" rel="nofollow">XYl-mBYzkGFAbOA@C1WJLAAAAME"]
/>
[Tue Sep 24 11:29:44.867106 2019] [:error] [pid 3620:tid 140457073518336] [client 115.23.88.188:33227] [client 115.23.88.188] ModSecurity: Warning. Operator LT matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "33"] [id "981203"] [msg "Inbound Anomaly Score (Total Inbound Score: 2, SQLi=0, XSS=0): Request Missing an Accept Header"] [hostname "dedibox.biz"] [uri "/web_app/5add/cal/deposit_list.php"] [unique_id "@C1WJLAAAAME" rel="nofollow">XYl-mBYzkGFAbOA@C1WJLAAAAME"]
/>
[Tue Sep 24 11:32:37.675222 2019] [:error] [pid 3620:tid 140456964908800] [client 187.95.253.151:60386] [client 187.95.253.151] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "29"] [id "960008"] [rev "2"] [msg "Request Missing a Host Header"] [severity "WARNING"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_HOST"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/"] [unique_id "@C1WJLQAAAMU" rel="nofollow">XYmARRYzkGFAbOA@C1WJLQAAAMU"]
/>
[Tue Sep 24 11:32:37.675341 2019] [:error] [pid 3620:tid 140456964908800] [client 187.95.253.151:60386] [client 187.95.253.151] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "47"] [id "960015"] [rev "1"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_ACCEPT"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/"] [unique_id "@C1WJLQAAAMU" rel="nofollow">XYmARRYzkGFAbOA@C1WJLQAAAMU"]
/>
[Tue Sep 24 11:32:37.675409 2019] [:error] [pid 3620:tid 140456964908800] [client 187.95.253.151:60386] [client 187.95.253.151] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "66"] [id "960009"] [rev "1"] [msg "Request Missing a User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_UA"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/"] [unique_id "@C1WJLQAAAMU" rel="nofollow">XYmARRYzkGFAbOA@C1WJLQAAAMU"]
/>
[Tue Sep 24 11:32:37.905112 2019] [:error] [pid 3620:tid 140456964908800] [client 187.95.253.151:60386] [client 187.95.253.151] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "37"] [id "981204"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 7, SQLi=0, XSS=0): Request Missing a User Agent Header"] [hostname "dedibox.biz"] [uri "/index.php"] [unique_id "@C1WJLQAAAMU" rel="nofollow">XYmARRYzkGFAbOA@C1WJLQAAAMU"]
/>
[Tue Sep 24 11:45:58.429115 2019] [:error] [pid 2956:tid 140456763582208] [client 192.168.100.1:2418] [client 192.168.100.1] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "66"] [id "960009"] [rev "1"] [msg "Request Missing a User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_UA"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/login/parseToken"] [unique_id "XYmDZmVb7RqOO9gTmuAAEwAAAAQ"]
[Tue Sep 24 11:45:58.435041 2019] [:error] [pid 2956:tid 140456755189504] [client 192.168.100.1:2419] [client 192.168.100.1] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "47"] [id "960015"] [rev "1"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_ACCEPT"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/assets/newkoad/bootstrap/js/popper.min.js.map"] [unique_id "XYmDZmVb7RqOO9gTmuAAFAAAAAU"]
[Tue Sep 24 11:45:58.438677 2019] [:error] [pid 2956:tid 140456755189504] [client 192.168.100.1:2419] [client 192.168.100.1] ModSecurity: Warning. Operator LT matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "33"] [id "981203"] [msg "Inbound Anomaly Score (Total Inbound Score: 2, SQLi=0, XSS=0): Request Missing an Accept Header"] [hostname "dedibox.biz"] [uri "/assets/newkoad/bootstrap/js/popper.min.js.map"] [unique_id "XYmDZmVb7RqOO9gTmuAAFAAAAAU"]
[Tue Sep 24 11:45:59.269606 2019] [:error] [pid 2956:tid 140456763582208] [client 192.168.100.1:2418] [client 192.168.100.1] ModSecurity: Warning. Operator LT matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "33"] [id "981203"] [msg "Inbound Anomaly Score (Total Inbound Score: 2, SQLi=0, XSS=0): Request Missing a User Agent Header"] [hostname "dedibox.biz"] [uri "/index.php"] [unique_id "XYmDZmVb7RqOO9gTmuAAEwAAAAQ"]
[Tue Sep 24 11:46:01.319440 2019] [:error] [pid 3620:tid 140456948123392] [client 192.168.100.1:2432] [client 192.168.100.1] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "66"] [id "960009"] [rev "1"] [msg "Request Missing a User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_UA"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/login/parseToken"] [unique_id "@C1WJMAAAAMc" rel="nofollow">XYmDaRYzkGFAbOA@C1WJMAAAAMc"]
/>
[Tue Sep 24 11:46:01.335269 2019] [:error] [pid 3620:tid 140456889374464] [client 192.168.100.1:2413] [client 192.168.100.1] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "47"] [id "960015"] [rev "1"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_ACCEPT"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/assets/newkoad/bootstrap/js/popper.min.js.map"] [unique_id "@C1WJMQAAAM4" rel="nofollow">XYmDaRYzkGFAbOA@C1WJMQAAAM4"]
/>
[Tue Sep 24 11:46:01.338886 2019] [:error] [pid 3620:tid 140456889374464] [client 192.168.100.1:2413] [client 192.168.100.1] ModSecurity: Warning. Operator LT matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "33"] [id "981203"] [msg "Inbound Anomaly Score (Total Inbound Score: 2, SQLi=0, XSS=0): Request Missing an Accept Header"] [hostname "dedibox.biz"] [uri "/assets/newkoad/bootstrap/js/popper.min.js.map"] [unique_id "@C1WJMQAAAM4" rel="nofollow">XYmDaRYzkGFAbOA@C1WJMQAAAM4"]
/>
[Tue Sep 24 11:46:02.160661 2019] [:error] [pid 3620:tid 140456948123392] [client 192.168.100.1:2432] [client 192.168.100.1] ModSecurity: Warning. Operator LT matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "33"] [id "981203"] [msg "Inbound Anomaly Score (Total Inbound Score: 2, SQLi=0, XSS=0): Request Missing a User Agent Header"] [hostname "dedibox.biz"] [uri "/index.php"] [unique_id "@C1WJMAAAAMc" rel="nofollow">XYmDaRYzkGFAbOA@C1WJMAAAAMc"]
/>
[Tue Sep 24 11:46:37.518582 2019] [:error] [pid 3620:tid 140456914552576] [client 39.170.148.138:17019] [client 39.170.148.138] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "98"] [id "960017"] [rev "2"] [msg "Host header is a numeric IP address"] [data "175.201.47.148"] [severity "WARNING"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/IP_HOST"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [tag "http://technet.microsoft.com/en-us/magazine/2005.01.hackerbasher.aspx"] [hostname "175.201.47.148"] [uri "/"] [unique_id "@C1WJMgAAAMs" rel="nofollow">XYmDjRYzkGFAbOA@C1WJMgAAAMs"]
/>
[Tue Sep 24 11:46:37.758317 2019] [:error] [pid 3620:tid 140456914552576] [client 39.170.148.138:17019] [client 39.170.148.138] ModSecurity: Warning. Operator LT matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "33"] [id "981203"] [msg "Inbound Anomaly Score (Total Inbound Score: 3, SQLi=0, XSS=0): Host header is a numeric IP address"] [hostname "175.201.47.148"] [uri "/index.php"] [unique_id "@C1WJMgAAAMs" rel="nofollow">XYmDjRYzkGFAbOA@C1WJMgAAAMs"]
/>
[Tue Sep 24 11:49:53.411451 2019] [:error] [pid 3620:tid 140456813840128] [client 187.95.253.151:48261] [client 187.95.253.151] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "29"] [id "960008"] [rev "2"] [msg "Request Missing a Host Header"] [severity "WARNING"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_HOST"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/"] [unique_id "@C1WJMwAAANc" rel="nofollow">XYmEURYzkGFAbOA@C1WJMwAAANc"]
/>
[Tue Sep 24 11:49:53.411573 2019] [:error] [pid 3620:tid 140456813840128] [client 187.95.253.151:48261] [client 187.95.253.151] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "47"] [id "960015"] [rev "1"] [msg "Request Missing an Accept Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_ACCEPT"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/"] [unique_id "@C1WJMwAAANc" rel="nofollow">XYmEURYzkGFAbOA@C1WJMwAAANc"]
/>
[Tue Sep 24 11:49:53.411643 2019] [:error] [pid 3620:tid 140456813840128] [client 187.95.253.151:48261] [client 187.95.253.151] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "66"] [id "960009"] [rev "1"] [msg "Request Missing a User Agent Header"] [severity "NOTICE"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/MISSING_HEADER_UA"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "dedibox.biz"] [uri "/"] [unique_id "@C1WJMwAAANc" rel="nofollow">XYmEURYzkGFAbOA@C1WJMwAAANc"]
/>
[Tue Sep 24 11:49:53.643917 2019] [:error] [pid 3620:tid 140456813840128] [client 187.95.253.151:48261] [client 187.95.253.151] ModSecurity: Warning. Operator GE matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "37"] [id "981204"] [msg "Inbound Anomaly Score Exceeded (Total Inbound Score: 7, SQLi=0, XSS=0): Request Missing a User Agent Header"] [hostname "dedibox.biz"] [uri "/index.php"] [unique_id "@C1WJMwAAANc" rel="nofollow">XYmEURYzkGFAbOA@C1WJMwAAANc"]
/>
[Tue Sep 24 12:37:31.346535 2019] [:error] [pid 2956:tid 140456721618688] [client 34.76.165.31:46630] [client 34.76.165.31] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_21_protocol_anomalies.conf"] [line "98"] [id "960017"] [rev "2"] [msg "Host header is a numeric IP address"] [data "175.201.47.148"] [severity "WARNING"] [ver "OWASP_CRS/2.2.9"] [maturity "9"] [accuracy "9"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/IP_HOST"] [tag "WASCTC/WASC-21"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [tag "http://technet.microsoft.com/en-us/magazine/2005.01.hackerbasher.aspx"] [hostname "175.201.47.148"] [uri "/"] [unique_id "XYmPe2Vb7RqOO9gTmuAAFQAAAAk"]
[Tue Sep 24 12:37:31.584168 2019] [:error] [pid 2956:tid 140456721618688] [client 34.76.165.31:46630] [client 34.76.165.31] ModSecurity: Warning. Operator LT matched 5 at TX:inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/modsecurity_crs_60_correlation.conf"] [line "33"] [id "981203"] [msg "Inbound Anomaly Score (Total Inbound Score: 3, SQLi=0, XSS=0): Host header is a numeric IP address"] [hostname "175.201.47.148"] [uri "/index.php"] [unique_id "XYmPe2Vb7RqOO9gTmuAAFQAAAAk"]
댓글목록
불량학생™님의 댓글
불량학생™ 쪽지보내기 메일보내기 자기소개 아이디로 검색 전체게시물 아이피 (175.♡.♡.145) 작성일
https://sir.kr/qa/314047
현재 이 글을 읽고 yum -y remove mod_security_crs 를 실행해서 지운상태입니다.
그런데도 500에러는 존재합니다.
그리고 서버에서 검색을 해보면
[root@cmsdb ~]# find / -name mod_security*
/etc/httpd/conf.d/mod_security.conf
/var/lib/mod_security
/usr/lib64/httpd/modules/mod_security2.so
/usr/share/doc/mod_security-2.9.2
/usr/share/doc/mod_security_crs-2.2.9
[root@cmsdb ~]#
이렇게 뜨네요